<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122965#M4472</link>
    <description>&lt;P&gt;Hi , same issue, in my organization , all in quarantine&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Antonio Foggia&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 11:12:28 GMT</pubDate>
    <dc:creator>afoggia</dc:creator>
    <dc:date>2021-07-05T11:12:28Z</dc:date>
    <item>
      <title>Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122953#M4469</link>
      <description>&lt;P&gt;Our users are getting a notification that the Ant-Malware blade has blocked a Python script.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="PythonScriptBlockNotification.jpg" style="width: 396px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12438i23E39AB2789A4994/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PythonScriptBlockNotification.jpg" alt="PythonScriptBlockNotification.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On investigation we found its actually Checkpoints own updater.&lt;/P&gt;&lt;P&gt;C:\ProgramData\CheckPoint\Endpoint Security\TPCommon\Updater\ATPS\Working\652743B2ED95EABB5DE5D88CDC51BF9E396216CD\cuckoo\protections\general\UID612340.pyc&lt;/P&gt;&lt;P&gt;Is there an actual issue with this script or should we add a manual exclusion for this ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CardView.jpg" style="width: 953px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12440iD44EA01F46D9256D/image-size/large?v=v2&amp;amp;px=999" role="button" title="CardView.jpg" alt="CardView.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:43:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122953#M4469</guid>
      <dc:creator>64Bit</dc:creator>
      <dc:date>2021-07-05T09:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122959#M4470</link>
      <description>&lt;P&gt;Hi there 64Bit,&lt;/P&gt;&lt;P&gt;Our users also started getting this alert at just after 4pm today, Perth, Western Australia time. I have a case logged with CP support so I'd be happy to let you know the outcome of that if you like? We've never experienced this issue before so safe to say you shouldn't have to add an exclusion but will confirm.&lt;/P&gt;&lt;P&gt;I was glad to see your post because I wanted confirmation it wasn't just us.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:46:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122959#M4470</guid>
      <dc:creator>BrockCap</dc:creator>
      <dc:date>2021-07-05T09:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122960#M4471</link>
      <description>&lt;P&gt;Please open a TAC case for this&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122960#M4471</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-05T09:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122965#M4472</link>
      <description>&lt;P&gt;Hi , same issue, in my organization , all in quarantine&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Antonio Foggia&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:12:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122965#M4472</guid>
      <dc:creator>afoggia</dc:creator>
      <dc:date>2021-07-05T11:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122999#M4477</link>
      <description>&lt;P&gt;Looks like a false positive in the Anti-Malware signatures.&lt;BR /&gt;New signatures should be available in the next few hours that address this.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:54:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122999#M4477</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-05T14:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint  blocked its own updater UID612340.pyc as Trojan</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/123322#M4484</link>
      <description>&lt;P&gt;Does anyone know if this file (UID612340.pyc) gets recreated or recompiled after the endpoint updates or if this file is even need for proper function of the endpoint?&amp;nbsp; Since the file was deleted there is no way to restore it but if it is not needed do we even concern ourselves with it?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 13:51:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/123322#M4484</guid>
      <dc:creator>Joe_Matthews</dc:creator>
      <dc:date>2021-07-08T13:51:02Z</dc:date>
    </item>
  </channel>
</rss>

